Ndakonzekera ndondomeko ya sitepe ndi sitepe kuti mutumize mosavuta VPN Load-Bancing Cluster monga teknoloji yowopsa kwambiri ya VPN.
Chitsanzo chomwe chili pansipa chidzakhala chosavuta potengera kutsimikizika ndi kuvomereza ma aligorivimu omwe amagwiritsidwa ntchito, koma idzakhala njira yabwino yoyambira mwachangu (yomwe pakali pano sikwanira kwa ambiri) ndi kuthekera kosintha mozama pazosowa zanu panthawi yotumiza. ndondomeko.
Zambiri mwachidule: Ukadaulo wa VPN Load Balancing Cluster siwolephera komanso si ntchito yophatikizira m'lingaliro lake, ukadaulo uwu ukhoza kuphatikiza mitundu yosiyana ya ASA (ndi zoletsa zina) kuti muthe kulumikiza kulumikizana kwa Remote-Access VPN. Palibe kulunzanitsa kwa magawo ndi masinthidwe pakati pa node za gulu loterolo, koma ndizotheka kunyamula zolumikizana za VPN ndikuwonetsetsa kulolerana kolakwika kwa maulumikizidwe a VPN mpaka node imodzi yogwira ikhalebe mgulu. Katundu mgululi amakhala wokhazikika malinga ndi kuchuluka kwa ntchito za node ndi kuchuluka kwa magawo a VPN.
Kwa failover ya node yeniyeni ya cluster (ngati ikufunika), filer ingagwiritsidwe ntchito, kotero kugwirizana kogwira kudzayendetsedwa ndi Node Yoyamba ya fayilo. The fileover sizinthu zofunikira kuti zitsimikizire kulolerana kwa zolakwika mkati mwa gulu la Load-Bancing, gululo palokha, ngati node yalephera, idzasamutsira gawo la ogwiritsa ntchito kumalo ena amoyo, koma popanda kupulumutsa kugwirizana, zomwe ziri ndendende. zoperekedwa ndi filer. Chifukwa chake, ndizotheka, ngati kuli kofunikira, kuphatikiza matekinoloje awiriwa.
Gulu la VPN Load-Bancing litha kukhala ndi ma node opitilira awiri.
VPN Load-Bancing Cluster imathandizidwa pa ASA 5512-X ndi pamwambapa.
Popeza ASA iliyonse mkati mwa gulu la VPN Load-Bancing ndi gawo lodziyimira pawokha malinga ndi zoikamo, timachita masitepe onse pa chipangizo chilichonse.
The logic topology yachitsanzo chomwe chaperekedwa:
Kutumiza Koyambirira:
Timatumiza zitsanzo za ASAv za ma tempuleti omwe tikufuna (ASAv5/10/30/50) kuchokera pachithunzichi.
Timagawira mawonekedwe a INSIDE / OUTSIDE ku ma VLAN omwewo (Kunja kwa VLAN yake, INSIDE mwayokha, koma kawirikawiri mkati mwa gululo, onani topology), ndikofunikira kuti ma interfaces amtundu womwewo akhale gawo limodzi la L2.
Zilolezo:
Pakadali pano kuyika kwa ASAv sikukhala ndi ziphaso zilizonse ndipo kungokhala 100kbps.
Kuti ASDM igwire ntchito, muyenera kuitsitsa koyamba patsamba la cisco.com, ineyo ndi fayilo ili:
Kuti kasitomala wa AnyConnect agwire ntchito, muyenera kukweza chithunzi ku ASA iliyonse pakompyuta iliyonse ya OS yomwe imagwiritsidwa ntchito (yokonzekera kugwiritsa ntchito Linux / Windows / MAC), mudzafunika fayilo yokhala ndi Phukusi la Headend Deployment Mumutu:
Mafayilo otsitsidwa amatha kukwezedwa, mwachitsanzo, ku seva ya FTP ndikukwezedwa kwa ASA aliyense payekha:
Timakonza setifiketi ya ASDM ndi Self-signed ya SSL-VPN (ndikofunikira kugwiritsa ntchito satifiketi yodalirika popanga). FQDN yokhazikitsidwa ya Virtual Cluster Address (vpn-demo.ashes.cc), komanso FQDN iliyonse yolumikizidwa ndi adilesi yakunja ya nodi ya gulu lililonse, iyenera kuthetseratu mu gawo lakunja la DNS kupita ku adilesi ya IP ya mawonekedwe a OUTSIDE (kapena ku adilesi yojambulidwa ngati kutumiza kwa doko udp/443 kukugwiritsidwa ntchito (DTLS) ndi tcp/443(TLS)). Zambiri pazofunikira pa satifiketi zafotokozedwa m'gawoli Chitsimikizo Chachiphaso zolemba.
!
vpn-demo-1(config)# crypto ca trustpoint SELF
vpn-demo-1(config-ca-trustpoint)# enrollment self
vpn-demo-1(config-ca-trustpoint)# fqdn vpn-demo.ashes.cc
vpn-demo-1(config-ca-trustpoint)# subject-name cn=*.ashes.cc, ou=ashes-lab, o=ashes, c=ru
vpn-demo-1(config-ca-trustpoint)# serial-number
vpn-demo-1(config-ca-trustpoint)# crl configure
vpn-demo-1(config-ca-crl)# cry ca enroll SELF
% The fully-qualified domain name in the certificate will be: vpn-demo.ashes.cc
Generate Self-Signed Certificate? [yes/no]: yes
vpn-demo-1(config)#
!
vpn-demo-1(config)# sh cry ca certificates
Certificate
Status: Available
Certificate Serial Number: 4d43725e
Certificate Usage: General Purpose
Public Key Type: RSA (4096 bits)
Signature Algorithm: SHA256 with RSA Encryption
Issuer Name:
serialNumber=9A439T02F95
hostname=vpn-demo.ashes.cc
cn=*.ashes.cc
ou=ashes-lab
o=ashes
c=ru
Subject Name:
serialNumber=9A439T02F95
hostname=vpn-demo.ashes.cc
cn=*.ashes.cc
ou=ashes-lab
o=ashes
c=ru
Validity Date:
start date: 00:16:17 MSK Mar 19 2020
end date: 00:16:17 MSK Mar 17 2030
Storage: config
Associated Trustpoints: SELF
CA Certificate
Status: Available
Certificate Serial Number: 0509
Certificate Usage: General Purpose
Public Key Type: RSA (4096 bits)
Signature Algorithm: SHA1 with RSA Encryption
Issuer Name:
cn=QuoVadis Root CA 2
o=QuoVadis Limited
c=BM
Subject Name:
cn=QuoVadis Root CA 2
o=QuoVadis Limited
c=BM
Validity Date:
start date: 21:27:00 MSK Nov 24 2006
end date: 21:23:33 MSK Nov 24 2031
Storage: config
Associated Trustpoints: _SmartCallHome_ServerCA
Mukamagwiritsa ntchito cluster, ndikofunikira kwambiri kuti maukonde amkati amvetsetse kuti ndi ASA iti yobwereranso kwa ogwiritsa ntchito, chifukwa cha izi muyenera kugawanso njira / ma adilesi 32 operekedwa kwa makasitomala.
Pakadali pano, sitinakonze masango, koma tili kale ndi zipata za VPN zomwe zitha kulumikizidwa payekha kudzera pa FQDN kapena IP.
Tikuwona kasitomala wolumikizidwa patebulo lamayendedwe la ASA yoyamba:
Kuti gulu lathu lonse la VPN ndi netiweki yamakampani onse adziwe njira yopita kwa kasitomala wathu, tidzagawiranso chiwongolero chamakasitomala kukhala njira yosinthira, mwachitsanzo OSPF:
Tsopano tili ndi njira yopita kwa kasitomala kuchokera pachipata chachiwiri cha ASA-2 ndipo ogwiritsa ntchito olumikizidwa kuzipata zosiyanasiyana za VPN mkati mwa tsango amatha, mwachitsanzo, kulumikizana mwachindunji kudzera pa foni yam'manja yamakampani, komanso kubweza magalimoto kuchokera kuzinthu zomwe wogwiritsa ntchito akufuna. bwerani pachipata chomwe mukufuna VPN:
Tiyeni tipitirire kukonza gulu la Load-Bancing.
Adilesi 192.168.31.40 idzagwiritsidwa ntchito ngati Virtual IP (VIP - makasitomala onse a VPN adzalumikizana nawo poyamba), kuchokera ku adilesi iyi Master cluster ipanga REDIRECT ku node yodzaza masango. Osayiwala kulemba patsogolo ndikusintha mbiri ya DNS onse pa adilesi iliyonse yakunja / FQDN ya node iliyonse ya gulu, komanso VIP.
Pambuyo pa kulumikizidwa kwina kwa kasitomala, mbiriyi idzatsitsidwa yokha ndikuyika mu kasitomala wa AnyConnect, kotero ngati mukufuna kulumikiza, muyenera kungoisankha pamndandanda:
Popeza tidapanga mbiriyi pa ASA imodzi yokha pogwiritsa ntchito ASDM, musaiwale kubwereza masitepe a ma ASA ena mgululi.
Kutsiliza: Chifukwa chake, tidatumiza mwachangu gulu la zipata zingapo za VPN zokhala ndi zowongolera zokha. Kuwonjezera ma node atsopano pagulu ndikosavuta, ndikukulitsa kosavuta kopingasa potumiza makina atsopano a ASAv kapena kugwiritsa ntchito ma ASA a hardware. Makasitomala olemera a AnyConnect amatha kukulitsa kulumikizana kotetezeka kwakutali pogwiritsa ntchito Kaimidwe (chiwerengero cha boma), yogwiritsidwa ntchito mothandizana kwambiri ndi dongosolo la centralized control ndi access accounting Identity Services Engine.